News Room
16
Share
Lazarus Group Weaponizes Windows Kernel Zero-Day CVE-2026-68820 in Global Defense Espionage Campaign
criticalZero-Day Exploits

Lazarus Group Weaponizes Windows Kernel Zero-Day CVE-2026-68820 in Global Defense Espionage Campaign

North Korean threat actors are actively exploiting a use-after-free vulnerability in the Windows WinSock driver to deploy the FudModule rootkit against aerospace and defense targets.

20 August 2026Last updated 20 August 20265 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-68820
Source:
Check Point Research
Read Time:
5 min

Executive Summary

Recent intelligence from Check Point Research and Microsoft MSRC has confirmed the active exploitation of a critical zero-day vulnerability, tracked as CVE-2026-68820, by the North Korean-linked Lazarus Group. The campaign, a new iteration of the long-standing 'Operation Dream Job,' specifically targets employees within the defense, aerospace, and aviation sectors in Europe and India. By leveraging a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), attackers are gaining SYSTEM-level privileges to deploy sophisticated kernel-mode rootkits. This activity highlights a persistent trend where nation-state actors weaponize kernel vulnerabilities to bypass modern endpoint security solutions.

Threat Analysis

The Lazarus Group is utilizing fraudulent recruitment offers as the primary infection vector. Attackers reach out to high-value targets on professional networking platforms, posing as recruiters for major aerospace firms. The lure involves a PDF or executable disguised as a job description which, when opened, initiates a multi-stage infection chain. The ultimate goal is the deployment of the FudModule rootkit. According to SecurityWeek, this campaign is particularly dangerous because it targets Windows 11 builds 26100 and 26200, demonstrating the group's ability to stay current with the latest operating system updates.

Technical Details

CVE-2026-68820 is a use-after-free (UAF) vulnerability residing in afd.sys, the kernel-mode driver for Windows Sockets (WinSock). The exploit allows a local attacker to elevate their privileges from a standard user to SYSTEM. Once elevated, the Lazarus Group installs a new version of the FudModule rootkit. Technical analysis reveals that this version of FudModule includes advanced capabilities to disable Endpoint Detection and Response (EDR) telemetry by tampering with kernel callbacks. Furthermore, the rootkit has been updated to interfere with Windows Smart App Control, effectively blinding security software to subsequent malicious activities performed by the attackers.

Attribution Assessment

Intelligence analysts attribute this activity to the Lazarus Group (also known as Diamond Sleet or APT38) with high confidence. The attribution is based on the reuse of the 'Operation Dream Job' infrastructure, specific code overlaps in the FudModule rootkit, and the targeting of strategic sectors consistent with North Korean state interests. The use of kernel-level exploits to blind EDR is a hallmark of recent Lazarus operations, as noted in BleepingComputer's reporting.

Implications

The exploitation of CVE-2026-68820 represents a significant escalation in the threat landscape for the defense industrial base. Because the exploit operates at the kernel level, traditional user-mode security tools may fail to detect the initial compromise or the subsequent presence of the rootkit. The ability of the Lazarus Group to bypass EDR telemetry means that compromised organizations may suffer long-term, undetected data exfiltration, potentially compromising sensitive military and aerospace technologies.

Recommendations

Encrygma recommends that all organizations immediately apply the August 2026 Patch Tuesday updates provided by Microsoft, which address CVE-2026-68820. Security teams should also monitor for unusual activity involving afd.sys and audit for the presence of unauthorized kernel drivers. Additionally, high-value targets in the defense sector should be briefed on the risks of unsolicited recruitment offers and encouraged to verify the identity of recruiters through official corporate channels before opening any shared documents.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo